Cisco Adaptive Security Appliance Software and Firepower Threat Defense Software Web Services Information Disclosure Vulnerability
A flaw in Cisco ASA and FTD firewalls' web interface allows attackers to read sensitive information from device memory by sending specially crafted web requests, without needing to log in. This could expose passwords, encryption keys, and other confidential data.
A buffer tracking vulnerability in the web services parser of Cisco ASA and FTD allows an unauthenticated remote attacker to retrieve arbitrary memory contents via malformed GET requests to the web interface. The flaw stems from improper handling of invalid URLs, potentially leading to disclosure of sensitive credentials and cryptographic material. Exploitation requires network access to the web services interface and affects specific AnyConnect and WebVPN configurations.
Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →